NIS2 Incident Reporting and DMARC Aggregate Reports
NIS2 codifies a 24/72/30 incident-reporting clock. DMARC aggregate reports are one of the practical detection inputs — here’s how to wire them into the response cycle.
Archive
NIS2 codifies a 24/72/30 incident-reporting clock. DMARC aggregate reports are one of the practical detection inputs — here’s how to wire them into the response cycle.
NIS2 changes what MSPs themselves must do — both as in-scope ICT service managers and as suppliers to covered entities. The DMARC-practice implications, in detail.
NIS2 splits in-scope organisations into essential and important. Here’s what that means for DMARC posture, MSP commitments, and audit evidence.
The EU’s NIS2 directive raised the bar for cybersecurity hygiene across critical sectors. Here’s where DMARC fits in — what’s now expected, and what changed for MSPs.
The honest counter-essay — client profiles where DMARC-as-a-service breaks down. Knowing when to decline is what makes the rest profitable.
DMARC isn’t standing still. Here’s where email authentication is heading: tightening provider rules, BIMI adoption, MTA-STS, and emerging standards.
MTA-STS enforces TLS on incoming SMTP. TLS-RPT reports when it fails. Here’s how the two interlock and why you should deploy both together.
MTA-STS forces TLS on incoming SMTP — preventing downgrade attacks that intercept email in transit. How it works and why businesses should deploy it.
MTA-STS turns opportunistic TLS into enforced TLS, closing downgrade-attack vectors. Here’s the specific security gain and what it adds to DMARC.
TLS-RPT delivers JSON reports when senders can’t establish TLS to your domain. Here’s how to publish it, read the reports, and act on what they reveal.